Lucene search

K
githubGitHub Advisory DatabaseGHSA-7968-H4M4-GHM9
HistoryFeb 15, 2023 - 6:10 p.m.

No protection against brute-force attacks on login page

2023-02-1518:10:54
CWE-307
GitHub Advisory Database
github.com
17
login page
brute-force attacks
rate-limiting proxy
kiwi tcms
upgrade

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

59.0%

Impact

Previous versions of Kiwi TCMS do not impose rate limits which makes it easier to attempt brute-force attacks against the login page.

Patches

Users should upgrade to v12.0 or later.

Workarounds

Users may install and configure a rate-limiting proxy in front of Kiwi TCMS. For example nginx.

References

Disclosed by spyata

Affected configurations

Vulners
Node
kiwitcmsRange<12.0
VendorProductVersionCPE
*kiwitcms*cpe:2.3:a:*:kiwitcms:*:*:*:*:*:*:*:*

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

59.0%

Related for GHSA-7968-H4M4-GHM9